Just a little information if you are interested in some of the ways that one may get around your firewall...

Firstly, an attacker will need to gain access to your system through methods (known or unknown) in order to consistently go around your firewall... by this I mean, if the attacker gets in, he/she will need to then go through the clean up process so as you dont discover the actions in your logs. This is OK from the attackers point of view to have to do this once, but they dont want to have to do it every time.

They may then implant a small shell application, similar to netcat, but maybe customised just for them.

It is fairly easy to place data inside ping packets and many other types of packets that your firewall will see as "normal" traffic and therefore just let it go, but this is very difficult for you to detect unless you are really looking at it hard. As turbinater suggested, you may try etherreal which will enable you to drill right down to the heart of every packet.

Try not to get too paranoid about it.. it can rule your life, but its good to see that you have noticed the rogue processes and are asking questions about it.

A thought process that you may like to take into consideration is... I should also look at what is going out through my firewall and how I go about stopping it. To many people are only concerned about what can come in....

Good luck.